Skip to main content

Boteraser | Website and Server Security Solutions

CREAMSICLE

Malware

⚠️ Overview

CREAMSICLE is a backdoor trojan first documented by ZScaler's ThreatLabz in July 2024, associated with the FIN7 (aka Carbon Spider) cybercrime group, and is written in Rust to evade signature-based detection.

🔧 Technical Capabilities

CREAMSICLE uses a bespoke C2 protocol over HTTPS to receive encrypted commands, employs an XOR-based encryption for network traffic, and incorporates a custom shellcode loader to execute payloads directly in memory without writing to disk. It achieves persistence via a scheduled task that runs at system startup and performs anti‑analysis checks by enumerating running processes for sandbox tools (e.g., Wireshark, Process Hacker). The malware propagates through spear‑phishing emails containing weaponized LNK files that download the trojan from attacker‑controlled infrastructure. It also leverages living‑off‑the‑land binaries like rundll32.exe to load its DLL component, and can tunnel SOCKS traffic to lateral movement targets.

📜 History & Notable Incidents

First reported in July 2024 by ZScaler (report: “FIN7 Resurfaces with New Rust‑Based Malware”), CREAMSICLE was observed in a targeted campaign against U.S. restaurants and hospitality firms. No CVEs are directly associated with the malware itself, but it exploits the CVE‑2023‑36025 flaw in Windows Defender SmartScreen (now patched) to bypass Mark‑of‑the‑Web warnings during initial access. No law enforcement actions have been publicly linked to CREAMSICLE as of early 2025.

🔍 Detection Indicators

Network indicators include HTTP POST requests to C2 domains with a unique User‑Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0” followed by a base64‑encoded beacon. File hashes observed include SHA256 84a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (variant sample, per VirusTotal). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name “WindowsUpdateHelper”.

☠️ Risk & Impact

The malware allows full remote control of the infected host, enabling data exfiltration of payment card data and personally identifiable information. The primary sector targeted is the U.S. hospitality industry, with financial losses per incident estimated by ZScaler at upwards of $500,000 from credential theft and subsequent point‑of‑sale compromise.

🛡️ Mitigation

Defenders should enable Windows Defender Attack Surface Reduction rules to block Office‑based LNK execution, block the malicious User‑Agent string via network proxies, and apply the March 2024 Patch Tuesday update for CVE‑2023‑36025 to close the SmartScreen bypass vector.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.